• Septimaeus@infosec.pub
    link
    fedilink
    English
    arrow-up
    6
    ·
    edit-2
    4 days ago

    They do, so far. I test these machines for privacy claims as a hobby and have been a bit surprised to find Apple stuff mostly delivering on those claims. I’m used to seeing a lot of dark patterns in testing and it’s made me expect the worst, but so far they’ve followed through on (in particular) their end-to-end encryption and on-device processing guarantees. Security audit failures so far have appeared to be engineering oversights, and the ones I reported have been patched already.

    The majority of user data they collect appears to be optional analytics and diagnostics that are properly encrypted and anonymized using the same pooling strategy used for their built-in VPN service. They recently started doing processing off-device for some new features related to the Apple intelligence thing (I haven’t gotten around to testing most of that) but otherwise anything siri-related is indeed processed locally. You can toggle a setting to allow anonymized siri recordings to be sent to Apple for quality control but they ask you permission each time you reset a device and re-confirm when you install updates, which IMO is adequate.

    Edit: Yes this is the opposite of what the other guy said. He is, to put it delicately, talking out his ass. There are good reasons to hate Apple, such as the fact that it’s a massive soulless corporation raping the planet to make luxury electronics for affluent consumers, but for most of the rabid apple conspiracy theorists I find online the reasons seem to be far more selfish and petty than that.

      • Septimaeus@infosec.pub
        link
        fedilink
        English
        arrow-up
        4
        ·
        3 days ago

        They do, so far as anyone is aware.

        They do, so far as anyone is aware or can know, yes.

        I said “so far” because I think continuing to test their claims remains important, as they keep making new equipment and are a large public corporation whose only moral code is increasing shareholder value.

        But I’m not interested in conspiracy theories. Sorry.